CVE-2020-8231: Debian Linux

High severity, CVSS 7.5. EPSS: 3.8% chance of exploitation in the next 30 days.

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Haxx Libcurl: from 7.29.0, up to and including 7.71.1
  • Oracle Communications Cloud Native Core Policy: version 1.14.0 only
  • Siemens Sinec Infrastructure Network Services: before 1.0.1.1 (fixed in 1.0.1.1)
  • Splunk Universal Forwarder: from 8.2.0, before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.6 (fixed in 9.0.6); version 9.1.0 only

Published 2020-12-14. Last modified 2026-06-17.